PanamaTimes

Wednesday, Sep 17, 2025

WhatsApp attack: 'Tens of thousands' fall victim to Russian voice message ambush

WhatsApp attack: 'Tens of thousands' fall victim to Russian voice message ambush

A phishing attack designed to look like a WhatsApp voice message has already compromised tens of thousands of email accounts.

The tried-and-tested attack method appears to be a harmless email containing a link to a WhatsApp voice message.

But anyone clicking on the link is taken to a malicious website that attempts to install a virus on the victim’s device.

Cyber security researchers at California-based Armorblox report that nearly 28,000 mailboxes – across both Gmail and Microsoft’s Outlook program have been impacted by the ambush.

More worryingly, the company says the email attack comes from a valid Russian-based domain.

The experts say the ‘mailman.cbddmo.ru,’ domain is associated with an organisation known as the ‘Center for Traffic Safety of the Moscow Region’ – which is a part of the Russian Ministry of Internal Affairs.

The phishing email contains the subject line ‘New Incoming Voicemessage’ and is supposedly from a WhatsApp Notifier function.

The fake WhatsApp email containing a dangerous link


The security researchers say that, although it looks authentic, it’s actually a trick.

‘Upon clicking the “Play” link in the email, recipients were redirected to a page that attempts to install a trojan horse JS/Kryptik,’ explained Lauryn Cash from Armorblox.

‘This is a malicious obfuscated JavaScript code embedded in HTML pages that redirects the browser to a malicious URL and implements a specific exploit.’

‘The Armorblox research team was able to observe this attack on multiple customer tenants across Office 365 and Google Workspace. The potential total attack exposure was close to 28K mailboxes.’

Targeting WhatsApp users and zeroing in on voice messages make sense given the staggering amount of users the service has.


What is phishing, and why is it called phishing?
A Royal Mail scam has been making the rounds.

Phishing is the term applied to kind of electronic communications scam that aims to obtain private information, or to spread harmful malware, via the recipient.

The phenomenon takes its name from fishing due to the parallels in unaware targets being reeled in by bait.

The term was coined around 1996, according to Computer World, as internet scammers began using e-mail lures, setting out hooks to fish for passwords and financial data from the sea of Internet users.

Hackers commonly replace the letter f with ph, a nod to the original form of hacking known as phone phreaking.


Every day on WhatsApp, over 7 billion voice notes are sent back and forth as voice messages provide a quick alternative to a phone call.


Voice messages are especially preferred by older family members who want to avoid typing or even communicating in another language.

Obviously, if you see this email (or one that looks like it) land in your inbox, don’t click the link.

Newsletter

Related Articles

PanamaTimes
0:00
0:00
Close
US Launches New Pilot Program to Accelerate eVTOL Air Taxi Deployment
New OpenAI Study Finds Majority of ChatGPT Use Is Personal, Not Professional
Actor, director, environmentalist Robert Redford dies at 89
Florida Hospital Welcomes Its Largest-Ever Baby: Annan, Nearly Fourteen Pounds at Birth
Could AI Nursing Robots Help Healthcare Staffing Shortages?
In a politically motivated trial: Bolsonaro Sentenced to 27 Years for Plotting Coup After 2022 Defeat
In a highly politically motivated trial, Brazil’s Supreme Court finds former leader Bolsonaro guilty of plotting coup
Brazilian police say ex-President Bolsonaro had planned to flee to Argentina seeking asylum
Apple Introduces Ultra-Thin iPhone Air, Enhanced 17 Series and New Health-Focused Wearables
Nayib Bukele Points Out Belgian Hypocrisy as Brussels Considers Sending Army into the Streets
Brazil Braces for Fallout from Bolsonaro Trial by corrupted judge
Escalating Drug Trafficking and Violence in Latin America: A Growing Crisis
Uruguay, Colombia and Paraguay Secure Places at 2026 World Cup
The White House on LinkedIn Has Changed Their Profile Picture to Donald Trump
Trump Responds to Death Rumors – Announces 'Missile City'
Argentine President Javier Milei Evacuated After Stones Thrown During Campaign Event
Category 5 Hurricane in the Caribbean: 'Catastrophic Storm' with Winds of 255 km/h
Air Canada Begins Flight Cancellations Ahead of Flight Attendant Lockout
Southwest Airlines Apologizes After 'Accidentally Forgetting' Two Blind Passengers at New Orleans Airport and Faces Criticism Over Poor Service for Passengers with Disabilities
Mexico Extradites 26 Cartel Figures to the United States in Coordinated Security Operation
Asia-Pacific dominates world’s busiest flight routes, with South Korea’s Jeju–Seoul corridor leading global rankings
Spain Scraps F-35 Jet Deal as Trump Pushes for More NATO Spending
Trump Administration Increases Reward for Arrest of Venezuelan President Maduro to Fifty Million Dollars
All Five Trapped Miners Found Dead After El Teniente Mine Collapse
Nationwide Protests Erupt in Brazil Demanding Presidential Resignation
Mystery Surrounds Death of Brazilian Woman with iPhones Glued to Her Body
Absolutely 100% Realistic EVO Series Doll by EXDOLL (Chinese Company) used mainly for carnal purposes
Former Judge Charged After Drunk Driving Crash Kills Comedian in Brazil
Trump Steamrolls EU in Landmark Trade Win: US–EU Trade Deal Imposes 15% Tariff on European Imports
California Clinic Staff Charged for Interfering with ICE Arrest
Politics is a good business: Barack Obama’s Reported Net Worth Growth, 1990–2025
US Revokes Visas of Brazilian Corrupted Judges Amid Fake Bolsonaro Investigation
Brazil's Supreme Court Imposes Radical Restrictions on Former President Bolsonaro
Judge Criticizes DOJ Over Secrecy in Dropping Charges Against Gang Leader
Biden’s Doctor Pleads the Fifth to Avoid Self-Incrimination on President’s Medical Fitness
US Imposes New Tariffs on Brazilian Exports Amid Political Tensions
U.S. Enacts Sweeping Tax and Spending Legislation Amid Trade Policy Shifts
AI Raises Alarms Over Long-Term Job Security
House Oversight Committee Subpoenas Former Jill Biden Aide Amid Investigation into Alleged Concealment of President Biden's Cognitive Health
OpenAI Secures Multimillion-Dollar AI Contracts with Pentagon, India, and Grab
Brazilian Congress Rejects Lula's Proposed Tax Increase on Financial Transactions
Landslide in Bello, Colombia, Results in Multiple Casualties
Papa Johns pizza surge near the Pentagon tipped off social media before Trump's decisive Iran strike
Juncker Criticizes EU Inaction on Trump Tariffs
Minnesota Lawmaker Melissa Hortman and Husband Killed in Targeted Attack; Senator John Hoffman and Wife Injured
Wreck of $17 Billion San José Galleon Identified Off Colombia After 300 Years
Sole Survivor of Air India Crash Recounts Escape
Coinbase CEO Warns Bitcoin Could Supplant US Dollar Amid Mounting National Debt
UK and EU Reach Agreement on Gibraltar's Schengen Integration
Israeli Finance Minister Imposes Banking Penalties on Palestinians
×